Bug 1438534 - split-stack: firewall not purged on initial deployment
Summary: split-stack: firewall not purged on initial deployment
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-tripleo-heat-templates
Version: 11.0 (Ocata)
Hardware: Unspecified
OS: Unspecified
Target Milestone: rc
: 11.0 (Ocata)
Assignee: James Slagle
QA Contact: Gurenko Alex
Depends On:
TreeView+ depends on / blocked
Reported: 2017-04-03 16:54 UTC by James Slagle
Modified: 2017-05-17 20:17 UTC (History)
5 users (show)

Fixed In Version: openstack-tripleo-heat-templates-6.0.0-4.el7ost
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Last Closed: 2017-05-17 20:17:15 UTC
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Launchpad 1679234 0 None None None 2017-04-03 16:55:40 UTC
OpenStack gerrit 453207 0 None None None 2017-04-04 14:47:45 UTC
Red Hat Product Errata RHEA-2017:1245 0 normal SHIPPED_LIVE Red Hat OpenStack Platform 11.0 Bug Fix and Enhancement Advisory 2017-05-17 23:01:50 UTC

Description James Slagle 2017-04-03 16:54:42 UTC
As part of https://bugs.launchpad.net/tripleo/+bug/1657108, a bug was fixed where the initial firewall gets purged as part of the image build. This is needed because if you have by default REJECT rules in iptables, you can have problems with pacemaker initializing the cluster, see also https://bugs.launchpad.net/tripleo/+bug/1672216

We also need to perform the same purge steps in the deployed server bootstrap SoftwareConfig.

Comment 4 Gurenko Alex 2017-04-23 17:47:33 UTC
 Please disregard previous comment, it was wrongly posted. As of build 2017-04-20.2 this bug is still present.

[stack@undercloud-0 ~]$ rpm -q openstack-tripleo-heat-templates

Comment 5 Gurenko Alex 2017-04-23 17:53:03 UTC
I can see that following lines are present in deployed-server-bootstrap-rhel.sh

echo '# empty ruleset created by deployed-server bootstrap' > /etc/sysconfig/iptables
echo '# empty ruleset created by deployed-server bootstrap' > /etc/sysconfig/ip6tables

But unless manually executed on overcloud nodes, deployment does not move any further and fails after some time.

Comment 6 Gurenko Alex 2017-04-24 05:54:18 UTC
 I'm not sure what was happening yesterday, left 2 other deployments overnight both succeed. The only thing I did is executed fstrim on both servers prior to that. Marking it as verified for build 20.2

Comment 7 errata-xmlrpc 2017-05-17 20:17:15 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.